CVE-2018-6497

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
16/06/2018
Last modified:
07/11/2023

Description

Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:microfocus:cms_server:2018.05:*:*:*:*:*:*:*
cpe:2.3:a:microfocus:universal_cmbd_server:*:*:*:*:*:*:*:* 10.20 (including) 11.0 (including)